Arbitrary File Upload in SIM-PKH 2.4.1 by SourceForge
CVE-2018-25409
Key Information:
Badges
What is CVE-2018-25409?
SIM-PKH version 2.4.1 is susceptible to an arbitrary file upload vulnerability. Authenticated users can exploit this flaw by uploading malicious files through the 'fupload' parameter. This can occur via the 'aksi_pengurus.php' endpoint when the 'module' and 'act' parameters are set to 'pengurus' and 'update', respectively. The uploaded PHP files are stored in the 'foto' directory and executed on the web server, potentially allowing attackers to execute arbitrary code.
Affected Version(s)
SIM-PKH 2.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
